A tool that displays an organisation’s staff addresses, breach records or internal asset names to whoever typed the domain into a form is not providing intelligence. It is providing reconnaissance, and it is doing so to an audience it has not identified.
So the public output is deliberately thin: counts, categories and masked samples such as j***@example.com. Enough to establish that something exists and warrants attention. Not enough to be useful to anybody building a target list.
Detail beyond that requires domain verification and, where a third-party data source is involved, appropriate authorised access to it. That threshold exists to protect the people whose addresses are involved, who did not ask to be part of anyone’s assessment.